Security Scan Report: curv.cc

Redirected to: https://www.paypal.com/us/digital-wallet/manage-money/crypto

Submitted: Mar 15, 2026, 6:31:15 AMCompleted: Mar 15, 2026, 6:31:47 AMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 2 countries across 6 domains to perform 26 HTTP transactions. The main domain is paypal.com and was registered NaN years ago.

Submitted URL: https://curv.cc

Effective URL: https://www.paypal.com/us/digital-wallet/manage-money/cryptoRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Suspicious redirect to PayPal from an unranked domain; likely brand impersonation.

Risk Factors
Brand impersonation via meta tags on a non‑official domain
Domain mismatch (curv.cc vs. PayPal)
Unranked/low‑reputation domain used for brand redirection
Domain age information unavailable

Details

Page Title

Buy and Sell Crypto | Cryptocurrency Wallet | PayPal US

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

cryptocurrency blockchain

(48%)

Domain Information

The domain 'curv.cc' uses the .cc country-code top-level domain and has no subdomain. Count 4 characters in 'curv' holding one vowel versus three consonants. Segmentation suggests two words: cur, v. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://curv.cc

Page Load Overview

5.73s
Total Load Time
101
HTTP Requests
8
Domains
6.5 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:8,003 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain48% confidence
Type: spa
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
48%
e-commerce shopping
45%
finance banking
43%
technology software
40%
corporate
35%

Detected Features

Products
OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
21104.18.34.93United States
AS13335Cloudflare, Inc.
16172.64.152.85United States
AS13335Cloudflare, Inc.
16151.101.195.1United States
16172.217.16.163United States
AS15169Google LLC
16142.251.143.99United States
AS15169Google LLC
16146.75.121.21Frankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
1016--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18A544C7064246D3E536F12CDE9B9374591A3430ACFC21FD9E5EDCAB50BD8C9628232DA

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:OsWR1pUWa75OJMmFi14tez7g6bQ9lDbCZPE1iKXuzXL8lEvNW2jVve0n5:W7eFbQ9NCZPE1iKXuzXL86vNW2jte05

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:298251:cICZ7GDhiCBFIogBCDIAoQALzAQLGYMREVZ8JJBIQgMtELLHRUhIRDJgiCERigHMhCcBYS1ET2EEI9nBRBFhgAQQIBBCC0IB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffc3c3e7ffffcf
Perceptual Hash:f2684a4b6a64373d
Difference Hash:51099e170a08363f
Wavelet Hash:00cfc3c381e7ff81
Color Hash:#e06e6c

Scan History

Scan history not available

Unable to load historical scan data